Vulnerability record · CVE-2023-0126 · published 19 January 2023
CVE-2023-0126: SonicWall SMA1000 firmware pre-auth path traversal file disclosure
Sonicwall · Sma1000 Firmware
SMA1000 firmware version 12.4.2 contains a pre-authentication path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files and directories outside the web root. Because no credentials or user interaction are required and the exposed data is rated high confidentiality impact, internet-facing SMA1000 appliances are a direct target for credential and configuration theft.
Description
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary files and directories stored outside the web root directory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable file disclosure on an internet-facing appliance with a very high EPSS score, though no KEV listing or confirmed exploit is recorded.
What it is
SMA1000 firmware version 12.4.2 contains a pre-authentication path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files and directories outside the web root. Because no credentials or user interaction are required and the exposed data is rated high confidentiality impact, internet-facing SMA1000 appliances are a direct target for credential and configuration theft.
Impact
An attacker gains read access to arbitrary files on the appliance, which can expose credentials, session data and configuration secrets. There is no integrity or availability impact per the CVSS vector; the loss is disclosure only.
Attack surface
Reachable over the network via HTTP/HTTPS on the SMA1000 management or web interface (AV:N, PR:N, UI:N). No authentication and no user interaction are needed, so any host that can reach the appliance can attempt it.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware association is recorded in this data, but EPSS is very high at 0.727 (99.4th percentile), indicating strong predicted exploitation activity. The only references are the vendor advisory, so confirmed in-the-wild use is not established here.
What to do
- Upgrade SMA1000 firmware to the fixed release named in SonicWall advisory SNWLID-2023-0001; 12.4.2 is the affected version.
- Restrict network access to the SMA1000 web interface to trusted management networks or VPN, and remove direct internet exposure where possible.
- Rotate credentials, certificates and any secrets stored on or managed through the appliance, since file disclosure may have exposed them.
- Review appliance logs for traversal-style requests and treat any prior suspicious access as a potential compromise.
Detection
- Search web/proxy logs for path traversal patterns such as ../, ..%2f, %2e%2e%2f and encoded variants in requests to SMA1000 endpoints.
- Alert on requests to the SMA1000 interface from unexpected source IPs or geographies, especially unauthenticated requests returning 200 with file-like content.
- Monitor for access to sensitive paths outside the web root (configuration, credential or key files) in appliance and file access logs.
- Correlate any observed traversal attempts with subsequent authentication anomalies or new administrative sessions on the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0001 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0001 | Vendor Advisory |
Track CVE-2023-0126 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0126), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.